Illustration of a masked cybercriminal using a laptop, representing a cyberattack targeting a business network.

The first hour after discovering a cyberattack is critical. Acting quickly—and taking the right steps—can help limit damage, protect important evidence, and improve your chances of recovery. Here’s a straightforward action plan every small business should know.

If your business experiences a cyberattack, it’s easy to panic.

Whether you’ve discovered ransomware, suspicious emails, or signs that someone has accessed your systems without permission, the actions you take in the first hour can make a significant difference.

The good news is that you don’t need to be a cybersecurity expert to respond effectively.

Here’s what to do—and just as importantly, what not to do.

Don’t Make the Situation Worse

Before taking action, avoid these common mistakes:

  • ❌ Don’t switch the affected computer off unless absolutely necessary.
  • ❌ Don’t delete suspicious emails, ransom notes or warning messages.
  • ❌ Don’t start reinstalling software or attempting to “fix” the problem yourself.
  • ❌ Don’t discuss the incident using the affected email account if you suspect it’s been compromised.
  • ❌ Don’t rush into paying a ransom.

Preserving evidence helps your IT provider investigate what happened and recover your systems more effectively.

Step 1: Disconnect Affected Devices

If you believe a device has been compromised, disconnect it from your network immediately.

That means:

  • Unplugging the network cable
  • Turning off Wi-Fi
  • Disconnecting any other network connections

Isolating the device helps prevent malware or ransomware from spreading to other computers, servers or backups.

If possible, leave the computer powered on unless your IT provider advises otherwise.

Step 2: Call Your IT Provider

Contact your IT support provider by phone as soon as possible.

Avoid relying on email if there’s any chance your mailbox has been compromised.

If your business has cyber insurance, notify your insurer as early as possible too. Many policies require their incident response team to be involved from the beginning.

Step 3: Preserve the Evidence

Resist the temptation to clean up the affected computer.

Instead:

  • Leave suspicious emails where they are.
  • Keep ransom notes visible.
  • Take screenshots if helpful.
  • Avoid deleting files or reinstalling Windows.

The more evidence that’s available, the easier it is to understand how the attack happened and what data may have been affected.

Step 4: Contact Your Bank (If Money Was Stolen)

If you’ve transferred money to a scammer or believe your banking details have been compromised, contact your bank immediately.

The sooner you report fraudulent payments, the greater the chance they can be stopped or recovered.

Every minute counts.

Step 5: Secure Your Accounts

Using a different, trusted device, begin changing passwords for your most important accounts.

Start with:

  • Business email
  • Microsoft 365
  • Administrator accounts
  • Banking services
  • Password manager accounts

If Multi-Factor Authentication (MFA) isn’t already enabled, now is the time to turn it on.

Step 6: Report the Incident

Reporting a cyberattack not only helps protect your own business—it can also help prevent attacks on others.

Where you report the incident depends on where your business operates.

For UK businesses, incidents should be reported to the National Cyber Security Centre (NCSC) and Action Fraud where appropriate.

If customer or employee personal data has been exposed, you may also have legal obligations under GDPR to notify the Information Commissioner’s Office (ICO) within the required timeframe.

Your IT provider can help determine whether notification is necessary.


Should You Pay the Ransom?

If ransomware is involved, paying the ransom may seem like the quickest solution.

However, there’s no guarantee you’ll recover your data—even if payment is made.

Paying can also encourage further criminal activity and make your business a target for future attacks.

Before making any decision, speak to:

  • Your IT provider
  • Your cyber insurer
  • Law enforcement where appropriate

In some cases, free decryption tools already exist for certain ransomware variants, making payment unnecessary.

Prepare Before an Attack Happens

The best time to plan for a cyberattack is before one occurs.

Every business should have a simple incident response plan that includes:

  • Key emergency contact numbers
  • IT support and cyber insurance details
  • Backup locations and recovery procedures
  • A list of your most critical systems and accounts

You don’t need a lengthy document.

Even a single-page plan can save valuable time during a real incident.

Being Prepared Makes All the Difference

Cyberattacks are stressful, but responding quickly and calmly can significantly reduce the impact on your business.

Knowing who to contact, preserving evidence and isolating affected devices gives your IT team the best chance of containing the incident and getting your business back up and running as quickly as possible.

Want to make sure your business is prepared before an attack happens? Novo IT Ltd can help you review your security, strengthen your defences and create a practical incident response plan tailored to your business.

Article used with permission from The Technology Press.

Tags

Comments are closed